Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 744007 (CVE-2020-15960, CVE-2020-15961, CVE-2020-15962, CVE-2020-15963, CVE-2020-15964, CVE-2020-15965, CVE-2020-15966) - <www-client/{chromium,google-chrome}-85.0.4183.121: Multiple vulnerabilities (CVE-2020-{15960,15961,15962,15963,15965,15966,15964})
Summary: <www-client/{chromium,google-chrome}-85.0.4183.121: Multiple vulnerabilities ...
Status: RESOLVED FIXED
Alias: CVE-2020-15960, CVE-2020-15961, CVE-2020-15962, CVE-2020-15963, CVE-2020-15964, CVE-2020-15965, CVE-2020-15966
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://chromereleases.googleblog.com...
Whiteboard: A2 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2020-09-21 20:25 UTC by Stephan Hartmann (RETIRED)
Modified: 2020-09-29 18:12 UTC (History)
1 user (show)

See Also:
Package list:
www-client/chromium-85.0.4183.121 amd64 arm64 dev-libs/re2-0.2020.08.01
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stephan Hartmann (RETIRED) gentoo-dev 2020-09-21 20:25:46 UTC
See ${URL}.

www-client/google-chrome already done.
Comment 1 Larry the Git Cow gentoo-dev 2020-09-22 07:21:51 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f286ddf3c1d0604be9c2be05ed22170ee494120f

commit f286ddf3c1d0604be9c2be05ed22170ee494120f
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-09-22 07:20:22 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-09-22 07:21:38 +0000

    www-client/chromium: stable channel bump to 85.0.4183.121
    
    Bug: https://bugs.gentoo.org/744007
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/chromium/Manifest                      |   1 +
 www-client/chromium/chromium-85.0.4183.121.ebuild | 867 ++++++++++++++++++++++
 2 files changed, 868 insertions(+)
Comment 2 Larry the Git Cow gentoo-dev 2020-09-22 12:37:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=0315bcafedf89affe1218f9cbf50033a8d2cf5aa

commit 0315bcafedf89affe1218f9cbf50033a8d2cf5aa
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-09-22 12:36:51 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-09-22 12:37:12 +0000

    www-client/vivaldi: Old
    
    Package-Manager: Portage-3.0.8, Repoman-3.0.1
    Bug: https://bugs.gentoo.org/744007
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 www-client/vivaldi/Manifest                      |   4 -
 www-client/vivaldi/vivaldi-3.3.2022.45_p1.ebuild | 125 -----------------------
 2 files changed, 129 deletions(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=939989ded2bef56cc9fd9c97c97fca6c8eb6eeac

commit 939989ded2bef56cc9fd9c97c97fca6c8eb6eeac
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-09-22 12:35:58 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-09-22 12:37:10 +0000

    www-client/vivaldi: Stable
    
    Package-Manager: Portage-3.0.8, Repoman-3.0.1
    Bug: https://bugs.gentoo.org/744007
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 www-client/vivaldi/vivaldi-3.3.2022.47_p1.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=28d8cd503a09d9fe3d6b78fd40bffea243b9b220

commit 28d8cd503a09d9fe3d6b78fd40bffea243b9b220
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2020-09-22 12:34:46 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2020-09-22 12:37:09 +0000

    www-client/vivaldi: Version 3.3.2022.47_p1
    
    Package-Manager: Portage-3.0.8, Repoman-3.0.1
    Bug: https://bugs.gentoo.org/744007
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 www-client/vivaldi/Manifest                      |   4 +
 www-client/vivaldi/vivaldi-3.3.2022.47_p1.ebuild | 125 +++++++++++++++++++++++
 2 files changed, 129 insertions(+)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-09-22 19:28:01 UTC
amd64 done
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-09-22 19:33:39 UTC
arm64 stable
Comment 5 Larry the Git Cow gentoo-dev 2020-09-22 19:39:48 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7af3986ca3ee12d931e44e355a2732a0825ad646

commit 7af3986ca3ee12d931e44e355a2732a0825ad646
Author:     Stephan Hartmann <sultan@gentoo.org>
AuthorDate: 2020-09-22 19:39:14 +0000
Commit:     Stephan Hartmann <sultan@gentoo.org>
CommitDate: 2020-09-22 19:39:14 +0000

    www-client/chromium: security cleanup
    
    Bug: https://bugs.gentoo.org/744007
    Package-Manager: Portage-3.0.4, Repoman-3.0.1
    Signed-off-by: Stephan Hartmann <sultan@gentoo.org>

 www-client/chromium/Manifest                      |   1 -
 www-client/chromium/chromium-85.0.4183.102.ebuild | 867 ----------------------
 2 files changed, 868 deletions(-)
Comment 6 Agostino Sarubbo gentoo-dev 2020-09-24 06:50:01 UTC
arm stable
Comment 7 Agostino Sarubbo gentoo-dev 2020-09-24 07:00:23 UTC
x86 stable.

Maintainer(s), please cleanup.
Comment 8 NATTkA bot gentoo-dev 2020-09-24 07:01:04 UTC
Resetting sanity check; keywords are not fully specified and arches are not CC-ed.
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2020-09-29 18:12:51 UTC
This issue was resolved and addressed in
 GLSA 202009-13 at https://security.gentoo.org/glsa/202009-13
by GLSA coordinator Sam James (sam_c).